Cyberattaque : des hackers font tomber des réseaux électriques !
A cyberattack attributed to Iranian-linked actors has reportedly disabled a small British power generation facility for four days, marking the first time a complete shutdown of such an installation has occurred in the UK. While the facility’s impact on the national grid was minimal due to its size, the incident highlights a growing trend of cyberattacks targeting critical infrastructure by actors associated with the Iranian regime. This event follows a series of similar attacks against US hydroelectric facilities, raising concerns about a coordinated campaign and the potential for further targeting of Western infrastructure. The incident underscores the importance of cybersecurity for energy providers and the need for enhanced defenses against state-sponsored actors.
A cyberattack, allegedly carried out by actors linked to Iran, has left a small British power generation facility offline for four days. According to The Telegraph, this is the first instance of a complete shutdown of a British power installation attributed to Iranian-linked actors. Michael Shanks, Minister for Energy, confirmed the existence of a cyber incident, stating that no electricity disruption was experienced by the population, and the smaller generator was significantly smaller than typical power plants. The incident follows a pattern of attacks against US hydroelectric facilities, with twelve states experiencing localized flooding and pressure drops in the preceding month, prompting a response from the White House.
The attack is being viewed as a potential strategic signaling operation, demonstrating Iran’s capabilities to disrupt critical infrastructure, even if the immediate impact on the national grid was limited. The incident has intensified concerns about a broader campaign targeting Western infrastructure by groups linked to Russia, China, Iran, and North Korea. Several sectors in the UK, including schools, the National Health Service (NHS), and Jaguar Land Rover, have previously suffered major cyberattacks.
Authorities are refusing to disclose details about the facility’s location and identity to ensure security. The FBI and the Environmental Protection Agency have issued a joint alert warning of attacks targeting programmable logic controllers (PLCs) – industrial automation systems – directly connected to the internet. These attacks have resulted in compromised operations, including changes to IP addresses and password activation/modification, leading to a loss of visibility and control. The alert specifically cites Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 PLCs as being targeted.
Beyond the immediate disruption, the incident emphasizes the strategic intelligence value of such attacks. The timing aligns with a series of operations targeting Iranian-linked actors in other countries, including Germany, Poland, Finland, Belgium, and Albania. The FBI and EPA are urging operators to eliminate direct internet exposure of PLCs, utilizing secure jump hosts and robust authentication. They recommend complex passwords, firewall rules, and disabling remote access unless absolutely necessary. The alert also highlights the importance of regularly reviewing logs and implementing measures to prevent unauthorized firmware changes.
Furthermore, the alert notes common network architectures among victims, suggesting a potential for replicating successful attack methods. The potential for PLC logic alteration – changing the underlying programming – poses a significant threat, impacting industrial processes directly. The incident underscores the need for proactive cybersecurity measures and a deeper understanding of the evolving threat landscape targeting critical infrastructure.
